highLogic errorEVM-Solidity
SEDA Protocol: Attacker can exploits batch sender role to block result Submissions via fee transfer reversion
- Payout
- $0
- Protocol
- SEDA Protocol
- Disclosed
- Mar 10, 2025
- Source
- sherlock
SEDA's SedaCoreV1 lets any address post a validator-signed batch and become its batch sender, which later entitles them to batchFee rewards paid in native tokens. Because the batch sender is set to msg.sender with no allowlist, an attacker can front-run a legi …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.